Something shifted quietly in early 2026, and most developers missed it.

Google Gemini API keys — previously treated as low-stakes configuration strings — now carry the same breach risk as payment credentials or OAuth tokens. That's not hyperbole. It's a direct consequence of how Gemini's billing model changed.

For years, Google's API key...